CVE-2018-17456
CRITICAL 9.8EPSS 97.4%
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.
- CVSS v3.0
- 9.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 97.36% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2018-10-06
- Updated
- 2024-08-05
Proof-of-concept exploits (7)
- 799600966/CVE-2018-174560★ · 2019-06-06
- AnonymKing/CVE-2017-10001173★ · 2019-06-21
- AnonymKing/CVE-2018-174565★ · 2019-06-22
- KKkai0315/CVE-2018-174560★ · 2024-07-22
- back2zero/GIT_CVE_2018_174560★ · 2018-10-09
- matlink/CVE-2018-174560★ · 2018-11-08
- shpik-kr/CVE-2018-174560★ · 2018-10-23